Cisco Webex Services Critical Improper Certificate Validation Flaw (CVE-2026-20184) Enables Man-in-the-Middle Against Cloud Meeting Traffic — Threadlinqs Intelligence
As of 2026-06-14, Cisco Webex Services Critical Improper Certificate Validation Flaw (CVE-2026-20184) Enables Man-in-the-Middle Against Cloud Meeting Traffic is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0376 · Severity: CRITICAL · CVSS: 9.1 · Status: PATCHED · Category: VULNERABILITY
Attribution: N/A · ESPIONAGE
Cisco has disclosed CVE-2026-20137, a critical improper certificate validation vulnerability (CVSS 9.1) in the cloud-based Webex Services platform. The flaw allows an unauthenticated remote attacker
On 2026-04-16 Cisco's Product Security Incident Response Team (PSIRT) released a batch of four critical security advisories affecting cloud-hosted Webex Services, Webex App clients, and on-premises integration components. The most severe of the batch, tracked as CVE-2026-20184, is an improper certificate validation vulnerability (CWE-295) in the TLS handshake logic of multiple Webex Services components responsible for brokering signaling between Webex App clients and the cloud meeting infrastructure.
The root cause is that specific subsystems within Webex Services failed to verify the full certificate chain, subject alternative name (SAN) binding, and revocation status of server certificates presented by peer components during service-to-service and client-to-service TLS setup. An attacker able to observe or redirect traffic between a Webex App client and webex.com / *.webex.com cloud endpoints — for example by controlling an upstream ISP, a rogue captive portal, a compromised VPN concentrator, or an attacker-controlled Wi-Fi access point — can present a forged or mis-issued certificate that the vulnerable component accepts without fully validating. Successful exploitation yields a man-in-the-middle position that enables the attacker to (1) decrypt meeting signaling and SIP/SDP exchanges, (2) harvest SSO bearer tokens and meeting join PINs relayed over the compromised channel, (3) inject modified control messages into active sessions, and (4) tamper with media negotiation to downgrade encryption parameters on secondary channels.
Cisco confirmed that no authentication or user interaction is required; the vulnerability is reachable pre-authentication in the public network path that every Webex client traverses to reach cloud tenants. Because the vulnerable logic resides primarily in Cisco's cloud-managed service mesh, Cisco has deployed a mitigating server-side fix that customers must pair with updated Webex App clients (versions 44.4.x and later) to obtain full protection. Earlier App clients continue to permit the weaker validation path until upgraded. The batch of four advisories collectively affects Webex Services, Webex App for Windows/macOS/Linux/iOS/Android, Webex Meetings virtual desktop plugins, and the Webex Hybrid Data Security node that bridges on-premises key material to the cloud.
While Cisco states it is not aware of public exploitation at disclosure time, the company observed attempted anomalous TLS negotiations against a small number of customer tenants during the preceding 60-day window, consistent with reconnaissance of the affected code path. Independent researchers at a European CERT replicated the attack end-to-end against lab Webex endpoints using a transparent proxy with a mis-signed wildcard, demonstrating full recovery of meeting join tokens and the ability to silently join otherwise-authenticated meetings as an invisible participant. The disclosure meaningfully elevates supply-chain MitM risk for enterprises, government tenants, and regulated industries that rely on Webex for privileged communications; operational telemetry suggests Webex cloud serves more than 95 million monthly active identities across more than 180 countries.
Weaknesses (CWE)
CWE-295, CWE-297, CWE-300
Target sectors: government, financial, healthcare, defense, legal, technology, energy, education, telecommunications, critical-infrastructure
Target regions: North America, Europe, Asia-Pacific, Latin America, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-20137, CVE-2026-20138, CVE-2026-20139, CVE-2026-20140, T1595, T1590, T1588, T1583, T1190, T1199, T1557, T1557.002, T1040, T1539